[CLSA-2024:1709561144] libssh: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2024-03-04 14:05:47 UTC
Description:
- CVE-2023-6004: fix the possibility of injections through a hostname parameter in the ProxyCommand/ProxyJump features - CVE-2023-6918: fix the issue when unchecked return values for digests may cause DoS
Updated packages:
  • libssh-0.9.4-3.el8.tuxcare.els3.i686.rpm
    sha:9ac87369b1a6d178ab7de532c672fe02fcaf9b20
  • libssh-0.9.4-3.el8.tuxcare.els3.x86_64.rpm
    sha:66740da058f49b4c9cce5a1c8ffa644e77a6ed5c
  • libssh-config-0.9.4-3.el8.tuxcare.els3.noarch.rpm
    sha:bae5f21333c47a021526c4a9b9655b2304c31a9d
  • libssh-devel-0.9.4-3.el8.tuxcare.els3.i686.rpm
    sha:a431746cafd8bf42fe50596e60b69035649d5fce
  • libssh-devel-0.9.4-3.el8.tuxcare.els3.x86_64.rpm
    sha:78146b3a7b46c7a5683083a019ce193924362f16
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.